Most people encrypt almost everything they do online and then, in the first few milliseconds of every connection, leak a plain text note about exactly where they are going. That note is the DNS lookup. Before your browser can reach a site, it asks a name server to translate the domain into an address, and for decades that request traveled the network in readable form. Your ISP sees it, anyone on the same Wi-Fi network can see it, and the logs of where you go get built whether you consented or not. Encrypted DNS, through standards called DNS over HTTPS and DNS over TLS, closes that hole. Here is what they actually protect, what they do not, and how to turn them on.
What DNS reveals and why it is valuable
A DNS query contains the domain name you are about to visit. That single line is more revealing than it sounds, because domain names are specific. A lookup for a particular bank says who you bank with. Lookups for a medical information site, a legal advice page, or a dating platform say something personal in a way that an encrypted HTTPS connection to a giant content network does not. Even though the pages you load afterwards are encrypted, the domain itself is the story, and the story is told before any encryption begins.
ISPs have a long documented history of monetizing and mishandling browsing data, and in several countries they have been required to keep DNS-level records of subscriber activity. In the UK, for example, retained communications data has been a feature of the legal landscape since the Investigatory Powers Act, and DNS logs are a natural place for that kind of retention to happen. Whatever your local rules are, the practical position is the same: plain text DNS means your access provider can build a browsing history of you, and you have no practical way to audit what they do with it.
DoH and DoT: same encryption, different plumbing
Two standards dominate encrypted DNS, and the difference is simpler than the acronyms suggest.
DNS over TLS, or DoT, runs on port 853. It is a separate encrypted channel dedicated to DNS. Because it uses a distinct port, network operators can see that you use it and, if they choose, block it. It is the standard that serious network administrators tend to deploy on their own infrastructure, precisely because it is a controlled, dedicated channel.
DNS over HTTPS, or DoH, runs on port 443, the same port as all ordinary web traffic, and looks like ordinary web traffic from the outside. That is its whole selling point. A network cannot block DoH without breaking the web, and cannot easily tell DNS queries apart from any other HTTPS request. This is the standard browsers use, and the standard that works on hostile networks: hotel Wi-Fi, corporate networks with filtering, mobile carriers that intercept plain text DNS to inject their own answers.
For an individual user, the practical recommendation is DoH. For a household or small business configuring a router, DoT on the router is the cleaner architecture, because then every device on the network benefits without individual setup.
What encrypted DNS does not hide
This is where honest expectations matter, because encrypted DNS is often oversold.
First, your DNS provider now sees everything your ISP used to see. You have moved the browsing history from one company to another. If you switch to a public DoH service, pick the provider with a privacy policy you actually believe, and remember that free services with no stated business model are monetizing something. Second, the site itself still knows you visited; encryption of DNS never hides that. Third, and most important: the encryption on the DNS channel does not hide the domain from a local network observer in every case, because for years the domain name has also been visible inside the TLS handshake itself, through a field called Server Name Indication. The industry’s fix for that is a newer standard called Encrypted Client Hello, or ECH, which is rolling out gradually across browsers and major hosting providers. Until ECH is everywhere, a local observer may still learn which domains you visit even with encrypted DNS, by watching the handshake instead of the lookup. Encrypted DNS removes the convenient bulk log your ISP could keep, not every possible observation point.
If your goal is broad protection against network-level tracking, the pieces must stack: encrypted DNS for the lookup layer, ECH or equivalent for the handshake layer, and awareness that the same Wi-Fi network’s other risks, like rogue access points capturing traffic, operate independently of all of this, as we covered in what a rogue access point actually captures.
How to enable it, device by device
On a desktop browser, the setting is a few clicks. In Firefox, open Settings, find the Network Settings section, enable DNS over HTTPS, and choose a provider. In Chrome, the equivalent lives under Privacy and security, then Security, with an option to use a secure DNS resolver. In both cases you can select the provider rather than accept the default, which matters if your default resolver is your ISP’s.
On Android, the clean way is a private DNS setting in the network options: enter the hostname of a DoT provider and the whole phone uses it, apps included. On iOS, encrypted DNS is configured through a profile or an app from a resolver provider, since Apple exposes the feature through configuration rather than a simple toggle.
On a home router, if the firmware allows it, change the upstream DNS servers to a DoT-capable resolver. This covers every device in the house, including the smart speakers and televisions that have no setting of their own. Those devices leak the most interesting data of all, as anyone who has looked at what a connected TV reports will know from our piece on how smart TV fingerprinting works.
Who should care, realistically
Encrypted DNS is one of the few privacy improvements that costs nothing and risks almost nothing. Speed differences are imperceptible on a good resolver, and failures are rare and loud when they happen. If you use any shared or untrusted network, hotel and airport Wi-Fi in particular, enabling it is close to mandatory. If you are the only user of a home connection and your only concern is your ISP’s logging, it removes the cheapest form of surveillance that exists against you, though it does not remove all of them, and it does nothing about tracking by the sites you actually visit.
It is a small lever, but the default state of DNS is genuinely bad: your complete map of destinations, readable by anyone positioned to look, since the web began. Turning on DoH takes under a minute and deletes a log you never agreed to keep. Do it for every device you control, and put DoT on your router so the devices you cannot control stop leaking too.


Leave a Reply